PT-2026-1699 · WordPress · Folders – Unlimited Folders To Organize Media Library Folder

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2025-12640

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress versions up to and including 3.1.5
Description The Folders plugin for WordPress is susceptible to unauthorized arbitrary media replacement. This occurs because of a lack of proper object-level authorization checks within the handle folders file upload() function. Authenticated attackers possessing Author-level access or higher can exploit this to replace any media file within the WordPress Media Library.
Recommendations Versions prior to and including 3.1.5 should be updated to a newer, fixed version of the plugin. As a temporary workaround, consider restricting access to the handle folders file upload() function for users with Author-level access or below.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12640

Affected Products

Folders – Unlimited Folders To Organize Media Library Folder